NeverHard

Senior Application Security Researcher at Kibbi — NeverHard

Senior Application Security Researcher at Kibbi in Toronto, Ontario. Skills: AI, AI Vulnerability Research, Application Security, BigQuery, CI/CD. Apply on NeverHard.

Company
Kibbi
Location
Toronto, Ontario
Type
full_time

Required skills:

The company secures the AI-driven SDLC from prompt to production, unifyingdevelopment and cloud context to stop vulnerabilities at the source. TheSecurity Research group is hiring a senior, hands-on Application SecurityResearcher to push modern AppSec forward — working with engineers, researchersand AI/data scientists on next-generation detection, including autonomous,agentic pen-testing capabilities. This is a build-and-break role, not a typicalAppSec position. Requirements 5+ years hands-on in offensive security, vulnerability research, orapplication security Deep understanding of web application and API vulnerabilities, includingbusiness-logic flaws and multi-step attack chains Strong coding in Python, Go, or similar, with production-quality code shipped Experience building or tuning detection logic (SAST, DAST, SCA, secrets, orcustom rule engines) and reducing false positives Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and atleast one major cloud provider Hands-on use of LLMs / AI models for security tasks, with the judgment tomeasure where they help and where they fail Comfort with large datasets (SQL, BigQuery, or similar) to drive research andmeasure detection accuracy Takes research ideas from prototype to production with minimal guidance Clear written communication — can explain a complex attack path to engineersand product managers M.Sc. in Computer Science, Cyber Security, or a related field Nice to have Published research, CVEs, conference talks, or a bug bounty track record Experience building AI agents or evaluation frameworks for LLMs Background in exploit development, red teaming, or penetration testing Code analysis techniques (taint analysis, call graphs, reachability) Contributions to open-source security tools #J-18808-Ljbffr